ZeroHour

CVE-2026-83461

moderate

Unauthenticated Data-Access and Partial DoS in Oracle EBS Mobile Application Server

CVSS 3.1
8.2 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83461 is a vulnerability in the MWA Terminal Server component of the Oracle Mobile Application Server within Oracle E-Business Suite, affecting releases 12.2.3 through 12.2.15. It is remotely exploitable by an unauthenticated attacker who has network access to the service over TCP, requiring no privileges or user interaction. A successful attack lets the attacker compromise the Mobile Application Server, gaining unauthorized access to critical data or to all data the server can reach, and the ability to cause a partial denial of service. The flaw carries a CVSS 3.1 base score of 8.2 (high), driven by high confidentiality impact and low availability impact, with no integrity impact. It is not listed in the CISA Known Exploited Vulnerabilities catalog and no public proof-of-concept is known, so no active exploitation has been observed.

What to do: Apply the Oracle Critical Patch Update that remediates this flaw on any E-Business Suite 12.2.3-12.2.15 environment running the MWA Terminal Server. Restrict TCP access to the MWA service to trusted warehouse/mobile-device networks via firewall rules, and do not expose it to the internet. Review MWA server logs for unexplained unauthenticated connections or data access and performance degradation consistent with attempted exploitation.

Affected
Oracle E-Business Suite Mobile Application Server (MWA Terminal Server)12.2.3-12.2.15
Estimated exposure
moderatelikely low thousands of organizations running EBS 12.2 with MWA deployed; internet-exposed instances likely in the hundreds or fewer — Oracle E-Business Suite has an install base estimated in the tens of thousands of enterprises (predominantly 12.2.x), but only a subset runs the Mobile Application Server / mobile supply chain functionality, and MWA terminal ports are…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Mobile Application Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Mobile Application Server accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Mobile Application Server. CVSS 3.1 Base Score 8.2 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L

In the news

No ingested article mentions this CVE yet.